The tourism industry is concerned about the emergence of a new form of organized electronics fraud, which targets travelers who have already made reservations through known international platforms such as Booking.com, Expedia and other popular online booking services.
The issue came to the fore following reports by hotel managers from various regions of the country, while the Head of Inspections, Auditors and Tourism Development of Thessaly of the Ministry of Tourism, Nicholas Sarukos, also issued a public warning calling on both tourism professionals and travelers to show increased attention.
According to information so far, travelers who have made reservations at hotels or tourist accommodation receive short written messages (SMS) from telephone numbers with international codes, mainly from Latin American countries. The messages are shown as official notices regarding their reservation and call on them to confirm or update their payment details through an electronic link.
The new fraud incidents come to be added to a series of cyber attacks recorded in recent years internationally in the area of tourism and hospitality. Hotel units, travel agencies and electronic platforms are often a target of skill, as they manage large amounts of personal and economic data.
It is noted that the relevant warning was issued during the three-day Holy Spirit and on a non-working day, indicating the seriousness with which the matter was addressed by the competent services. N. Sarukos immediately proceeded to inform the tourist market, with the aim of preventing possible cases of fraud against travellers and businesses.
Cybersecurity experts point out that this method is a classic electronic case «fishing» (Phishing), however, presents a particularly worrying feature: the fraudsters seem to know the actual details of their victims' detentions, such as the name of the accommodation, the dates of stay or even the customer's personal information. This raises serious questions about possible data leaks or hotel accounts violations and cooperating booking systems, such as known international platforms (e.g. Booking. com, Expedia etc.) and other popular online booking services.
How fraud works «Hijacking Reservation»
In particular, experts describe this method as «Hijacking Reservation» or «occupying reservation». In the first stage, cyber-criminals gain access to accommodation accounts or reservation data through violations, stolen codes or malicious software. They then send personalised messages via SMS, email, WhatsApp or other applications, using actual booking information. They usually call for an urgent problem:
- failed payment
- need to confirm the card
- issue of authorisation of the transaction
- risk of cancellation of the reservation.
The recipient is asked to click on a link that leads to a fake website, designed to resemble the environment of the booking platform or hotel. There he is asked to introduce his credit card details, bank codes or other sensitive information, which end up directly in the hands of the perpetrators.
Because scams get more threatening
New cybersecurity surveys show that customer data and travel booking data usually leak from hundreds of hotel units internationally. According to Norton's analysis, more than 350 hotels, hostels and tourist accommodation in around 50 countries appear to have been affected by recent incidents of travel platform data leakage. This information is exploited by cyber criminals to create highly targeted phishing attacks.
Experts point out that the use of actual booking data makes fraudulent messages much more convincing. When the traveler sees his name, the hotel he has chosen, even the exact check-in and check-out dates, is much more likely to consider the message authentic. At the same time, the development of automated tools «phishing-as-a-service», now allows the mass dispatch of personalised messages to thousands of potential victims at a minimum cost to the perpetrators.
Risk to business
Another widespread method concerns fraudsters trying to extract money from tourist businesses, pretending to represent known airlines and promoting alleged business cooperation proposals. In these e-mails they claim to start new activities or expand their initiatives and say they actively seek suppliers or external partners. If a member of a company's staff responds, the perpetrators usually go to the next stage. In order to enhance their credibility, they shall send forged documents to be completed and signed, including forms for the registration of suppliers and confidentiality agreements.
The ultimate objective of the perpetrators using this method is to persuade the company to pay a so-called «advance», which is supposed to be required to ensure priority on a list of prospective partners. The perpetrators claim that this amount will be fully reimbursed after formalisation of the cooperation. In fact, this promise is completely misleading, as the perpetrators distract money and never return it to the business.

